Performance impact
Performance impact
Posted Aug 5, 2022 1:28 UTC (Fri) by Cyberax (✭ supporter ✭, #52523)In reply to: Performance impact by cschaufler
Parent article: Security requirements for new kernel features
> When LSM was introduced the additional restrictions provided were only used by a handful of government and affiliated agencies.
And it's pretty much used in these situations now. SELinux is useful if you are a giant corp with a huge development staff that is OK with torturing themselves by writing SELinux policies.
> Today the system that doesn't use security modules is an odd duck indeed.
Like, pretty much all classic desktops? I've yet to see a developer with "serious" LSMs like SELinux turned on.
I think, some serious soul-searching on the side of LSM developers is in order.
